AI compliance obligations for a wealth management firm in the US

AI compliance obligations for a wealth management firm in the US

4 AI-adoption compliance obligations apply, each cited to primary law.

Keep the records of advice the AI helps produce

Rule: Advisers Act Rule 204-2 (Books & Records)

What it requires: A registered investment adviser must make and keep true, accurate and current books and records relating to its advisory business, including recommendations and communications with clients. Work an AI system drafts, screens or supports is part of that advisory record.

Do this: Log which AI tool was used, on what input, and who reviewed the output, retained with the underlying advisory record for the required period, so the books-and-records obligation is met whether or not a model was in the loop.

Source: Investment Advisers Act of 1940, Rule 204-2 (17 CFR 275.204-2).

Confidence: Verify

Adopt written policies governing your AI use

Rule: Advisers Act Rule 206(4)-7 (Compliance)

What it requires: An adviser must adopt and implement written policies and procedures reasonably designed to prevent violation of the Advisers Act, and review them at least annually. Deploying AI in advisory workflows is a change that those policies must address.

Do this: Add AI governance to your compliance manual — approved tools, human-review checkpoints, data handling, and testing — and cover it in the annual compliance review.

Source: Investment Advisers Act of 1940, Rule 206(4)-7 (17 CFR 275.206(4)-7).

Confidence: Verify

AI-generated marketing and client communications must be fair and substantiated

Rule: Marketing Rule 206(4)-1

What it requires: The Investment Adviser Marketing Rule prohibits untrue or misleading statements in advertisements and requires the adviser to have a reasonable basis for claims. AI that drafts marketing copy, performance summaries or client-facing material is producing content that must meet this standard.

Do this: Route any AI-drafted advertisement or client communication through marketing-rule review before it goes out, and keep records substantiating the claims it makes.

Source: Investment Advisers Act of 1940, Rule 206(4)-1 (17 CFR 275.206(4)-1), the Marketing Rule.

Confidence: Verify

Have an incident-response program and meet the breach-notice timeline

Rule: Regulation S-P (Release 34-100155)

What it requires: Under the Regulation S-P amendments adopted 15 May 2024, SEC-registered advisers and broker-dealers must maintain a written incident-response program and, following a breach involving sensitive customer information, notify affected individuals as soon as practicable and no later than 30 days. Client data flowing into AI tools falls within this safeguard duty.

Do this: Map which AI tools touch customer information, bring them inside your Reg S-P safeguards and incident-response program, and confirm your breach-notice process can meet the 30-day deadline.

Source: SEC Release No. 34-100155 (Regulation S-P amendments, adopted 15 May 2024); 17 CFR 248.30.

Confidence: Verify